4.5 Article

Image-based malware classification using section distribution information

期刊

COMPUTERS & SECURITY
卷 110, 期 -, 页码 -

出版社

ELSEVIER ADVANCED TECHNOLOGY
DOI: 10.1016/j.cose.2021.102420

关键词

Malware classification; Malware visualization; Gray images; Machine learning; Deep learning

资金

  1. National Natural Science Foundation of China [62062022]
  2. Science and Technology Foundation of Guizhou Province [[2020] 1Y268]
  3. Open Project of Guizhou Provincial Key Laboratory of Public Big Data [2017BDKFJJ025]

向作者/读者索取更多资源

This paper presents a malware classification method based on PE files, using a new visualization method and deep learning technology to improve the accuracy and efficiency of malware classification.
Recently, with the rapid increase in the number of malware, the traditional machine learning-based malware classification methods are faced with the severe challenge of ef-ficiently and accurately detecting a large number of malicious programs. To meet this chal-lenge, malware classification based on malware image and deep learning has become an effective solution. However, it is difficult to identify the section distribution information such as the number, order, and size of sections from the current gray images converted by the binary sequences of PE files. Therefore, this article proposes a novel visualization method that introduces the Colored Label boxes (CoLab) to mark the sections of a PE file to further emphasize the section distribution information in the converted malware image. Moreover, a malware classification method called MalCVS (Malware classification using Co-Lab image, VGG16, and Support vector machine) is constructed. The experimental results of the malware collected from VX-Heaven and Virusshare as well as the Microsoft Malware Classification Challenge dataset showed that MalCVS can effectively classify malware into families with high accuracy. The average accuracies of MalCVS are respectively 96.59% and 98.94% on the two datasets. (c) 2021 Elsevier Ltd. All rights reserved.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.5
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据